ATT&CKReferencesRecordedFuture RedEcho 2022

RecordedFuture RedEcho 2022

Recorded Future Insikt Group. (2022, April 6). Continued Targeting of Indian Power Grid Assets by Chinese State-Sponsored Activity Group. Retrieved November 21, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns1

Procedure examples3

TechniqueUsed byProcedure example
T1584
Compromise Infrastructure
CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions included the use of compromised infrastructure, such as DVR and IP camera devices, for command and control purposes in ShadowPad activity.

T1588.004
Digital Certificates
CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions included the use of digital certificates spoofing Microsoft.

T1599
Network Boundary Bridging
CampaignIndian Critical Infrastructure Intrusions

Indian Critical Infrastructure Intrusions involved the use of FRP to bridge network boundaries and overcome NAT. Indian Critical Infrastructure Intrusions also involved the use of VPN tunnels with a potentially compromised MSP entity allowing for direct access to critical infrastructure entity networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.